Conceptual Framework for The Protection of Critical Information Infrastructure Against Supply Chain Threats
Authors
Ayaeze Paul
Centre for Cyberspace Studies, Nasarawa State University, Keffi (NSUK) (NG)
Ozogwu Young
Centre for Cyberspace Studies, Nasarawa State University, Keffi (NSUK) (NG)
Victor Kulugh
Department of Cybersecurity, Bingham University, Karu, Nigeria (NG)
Ajishe Oyelola
Centre for Cyberspace Studies, Nasarawa State University, Keffi (NSUK) (NG)
Achimugu Andrew
Centre for Cyberspace Studies, Nasarawa State University, Keffi (NSUK) (NG)
Akiga Jessica
Centre for Cyberspace Studies, Nasarawa State University, Keffi (NSUK) (NG)
Akinremi Soji
Centre for Cyberspace Studies, Nasarawa State University, Keffi (NSUK) (NG)
Nwokocha Patrick
Centre for Cyberspace Studies, Nasarawa State University, Keffi (NSUK) (NG)
Idris Muhammad
Centre for Cyberspace Studies, Nasarawa State University, Keffi (NSUK) (NG)
Ahiaba Moses
Centre for Cyberspace Studies, Nasarawa State University, Keffi (NSUK) (NG)
Article Information
DOI: 10.51583/IJLTEMAS.2025.1408000128
Subject Category: Cybersecurity
Volume/Issue: 14/8 | Page No: 987-994
Publication Timeline
Submitted: 2025-09-13
Published: 2025-09-13
Abstract
Abstract: The backbone of modern economies relies heavily on Critical Information Infrastructure (CII). It helps to provide critical services in the energy, finance, telecommunications, health, and transportation sectors. This growing dependences on third-party vendors, software applications, and supply chains, has exposed CII to formidable cyber risks. Recent attacks like SolarWinds, NotPetya, and Colonial Pipeline show how damaging supply chain cyber-attacks can be. They threaten both national security and economic stability. This paper hence presents a general conceptual framework that protects CII against supply chain threats. Anchored on the DSR approach, the paper synthesizes some of the literature on prior cybersecurity frameworks, models of supply chain risk, and resilience strategies. The proposed framework integrates three layers: Risk Identification, Governance and Compliance, and Resilience and Response. These layers introduce AI-driven threat detection, ZTA, secure procurement policy, and automated mechanisms for incident response. A comparison of major cybersecurity frameworks such as NIST CSF, ISO/IEC 27001, C-SCRM, and the EU NIS2 Directive shows important gaps in risk assessment, regulation, and resilience strategies. The study therefore contributes to both the academic fraternity and industry practices through the presentation of a structured, adaptive model in mitigating evolving supply chain cyber risks. Future research on empirical validation, cross-border regulatory harmonization, and real-time risk quantification models will be useful in further enhancing global CII resilience.
Keywords
Critical Information Infrastructure (CII), Supply Chain Threat, Cyber Supply Chain Risk Management (C-SCRM), Zero Trust Architecture (ZTA), Threat Intelligence Monitoring
Downloads
References
1. Ahlqvist, O., Dewitz, J., & Raines, G. (2019). Multi-level governance models for securing critical infrastructure supply chains. Journal of Cybersecurity and Infrastructure Security, 15(3), 110-129. [Google Scholar] [Crossref]
2. Brucherseifer, J., Müller, K., & Lang, R. (2021). Digital twin conceptual framework for improving cyber resilience in supply chain security. Computers & Security, 105, 102178. https://doi.org/10.1016/j.cose.2021.102178 [Google Scholar] [Crossref]
3. Centre for Cyber Security. (2021). Supply chain attack against SolarWinds Orion Platform [Report]. Danish Defence Intelligence Service, Centre for Cyber Security. https://www.cfcs.dk/globalassets/cfcs/dokumenter/rapporter/en/CFCS-solarwinds-report-EN.pdf [Google Scholar] [Crossref]
4. CISA (Cybersecurity and Infrastructure Security Agency). (2020). Cyber Supply Chain Risk Management Practices for Federal Agencies and Critical Infrastructure. U.S. Department of Homeland Security. Retrieved from https://www.cisa.gov/c-scrm [Google Scholar] [Crossref]
5. European Union Agency for Cybersecurity (ENISA). (2023). NIS2 Directive: Strengthening Cyber Resilience for Critical Infrastructure in Europe. Retrieved from https://www.enisa.europa.eu/publications/nis2-directive [Google Scholar] [Crossref]
6. Giannopoulos, G., Jungwirth, R., & Hadjisavvas, C. (2023). Fortifying Defense: Strengthening Critical Energy Infrastructure Against Hybrid Threats. EU Cybersecurity Journal, 19(1), 45-63. [Google Scholar] [Crossref]
7. Henriksson, L. (2021). Cyber supply chain vulnerabilities: A strategic analysis of third-party risks in the ICT sector. Journal of Strategic Information Security, 14(2), 89-105. [Google Scholar] [Crossref]
8. ISO (International Organization for Standardization). (2021). ISO/IEC 27001: Information Security Management Systems. Retrieved from https://www.iso.org/isoiec-27001-information-security.html [Google Scholar] [Crossref]
9. Jenks, M. (2015). Risk-based procurement frameworks for securing critical supply chains: A comparative study of public and private sector practices. Security Journal, 28(4), 378-395. [Google Scholar] [Crossref]
10. Mbanaso, U., Cooper, G., & Gordon, P. (2019). ICT Dependency Index (IDI): Measuring cyber risk exposure in critical supply chains. International Journal of Cybersecurity Policy, 7(1), 58-72. [Google Scholar] [Crossref]
11. NIST (National Institute of Standards and Technology). (2018). Framework for Improving Critical Infrastructure Cybersecurity (Version 1.1). U.S. Department of Commerce. Retrieved from https://www.nist.gov/cyberframework [Google Scholar] [Crossref]
12. NIST (National Institute of Standards and Technology). (2021). Zero Trust Architecture: Implementing Continuous Authentication in Critical Infrastructure. U.S. Department of Commerce. Retrieved from https://www.nist.gov/publications/zero-trust-architecture [Google Scholar] [Crossref]
13. The White House. (2021, May 17). Executive Order 14028: Improving the nation’s cybersecurity. Federal Register, 86(93), 26633–26647. https://www.federalregister.gov/documents/2021/05/17/2021-10460/improving-the-nations-cybersecurity [Google Scholar] [Crossref]
14. Weiß, M. (2023). Cyber supply chain security: Addressing third-party risks in critical infrastructure operations. International Journal of Cybersecurity Research, 22(4), 199-218. [Google Scholar] [Crossref]
Metrics
Views & Downloads
Similar Articles
- Advanced Techniques for Fake News Detection on Twitter Using NLP and AI: A Comprehensive Review
- Review of Self Compacting Geopolymer Concrete Using Slag Sand as Fine Aggregate
- Performance of Local Construction Contractors – Case Study of Registered Contractors in Monrovia, Liberia
- Cross-Cultural Perspectives on Innovation Management in Multinational Organizations
- Modeling of Reaction Between Dissolved Oxygen (DO) And Biological Oxygen Demand (BOD) in Degradation River